Skip to content
NEURIXIS

Privacy policy

Last updated : 07/2026

This policy explains what personal data NEURIXIS collects through this website, why, how long it is kept and how you keep control over it. Trackers are covered separately, in our cookie policy.

1. Who is responsible for your data

Data controller

NEURIXIS, SAS, société par actions simplifiée (a French simplified joint stock company), whose registered office is at 60 rue François Ier, 75008 Paris, France, registered under SIREN 944 434 810 (RCS Paris), determines the purposes and means of the processing described here.

Point of contact

For any question, or to exercise your rights, write to hello@neurixis.ai, or by post to the registered office.

NEURIXIS has not appointed a data protection officer. An appointment is not required here: we are not a public authority, we do not carry out large-scale systematic monitoring and we do not process special category data on a large scale (article 37 of the GDPR). Your requests are handled at the address above.

2. A few definitions

GDPR vocabulary, in short

Personal data: any information that identifies you, directly or indirectly. Your work email address is personal data.

Processing: any operation performed on that data, from collection to erasure, including consultation and archiving.

Controller: the party that decides why and how the data is processed. Here, NEURIXIS.

Processor: a supplier that processes the data on our behalf and on our instructions, for example our host.

3. The data we collect

Workshop eligibility form

You send us your company name, your role, the company headcount, your industry, a description of the process you would like to improve and your work email address. These fields let us judge whether the workshop fits your need. Do not enter any special category data or trade secrets: a functional description is enough.

Technical browsing data

Our servers record technical logs (IP address, date and time of the request, page requested, browser type) to keep the service secure. Traffic measurement, by contrast, only produces aggregated statistics.

Unsolicited job applications

If you write to us to apply for a role, we keep your message and its attachments for as long as it takes to reply and consider your application.

4. Why we process it

Each processing activity rests on a specific legal basis and a defined retention period.

Purposes, legal bases and retention periods for the processing activities carried out by NEURIXIS.
PurposeData concernedLegal basisRetention
Handling a workshop eligibility request and getting back to youCompany, role, headcount, industry, description of the process, work email addressConsent (the tick box on the form)12 months from the request
Following up the business relationship after a first exchangeBusiness contact details, history of our exchangesLegitimate interest: maintaining a relationship with a prospect who approached us3 years from the last contact
Handling an unsolicited job application received by emailIdentity, contact details, CV and backgroundSteps taken at the request of the data subject prior to entering into a contract2 years from the last contact, unless the person is recruited
Measuring website traffic in aggregate formAggregated technical data: page views, referring page, device type, countryLegitimate interest: understanding how the site is used without individual trackingNo individual data retained
Keeping the website secure and availableServer technical logs, IP addressLegitimate interest: preventing abuse and incidents6 months
Meeting a legal obligation or establishing and defending legal claimsData strictly necessary for the caseLegal obligation or legitimate interestThe applicable limitation period

Where processing rests on our legitimate interest, we check that it remains proportionate and that your rights prevail in case of doubt. You can object to it at any time.

5. Who has access to your data

Recipients

Internally, only those people at NEURIXIS who handle your request have access: the sales team and the consultants concerned. Externally, we use the following processors, which act on our instructions under a contract binding them to confidentiality and security:

  • Scaleway SAS (France): hosting of the website and of the form data.
  • Brevo SAS (France): sending internal notifications and managing the business relationship. Your address is not added to any marketing mailing list: submitting the form is not consent to receive our communications.
  • Plausible Insights OÜ (Estonia): aggregated traffic measurement, with no cookie and no personal data.

If you accept measurement or marketing trackers, Google Ireland Limited and LinkedIn Ireland Unlimited Company also become recipients of the corresponding browsing data. The details are in the cookie policy.

We do not sell any data. We do not rent it out and we do not disclose it to anyone for advertising purposes.

6. Transfers outside the European Union

Principle and safeguards

We favour suppliers that host data within the European Union. If a transfer to a third country becomes necessary, we frame it with the European Commission’s standard contractual clauses, supplemented where needed by technical measures such as encryption. The list of suppliers concerned is available on request at the contact address.

7. How we protect it

Security measures

Exchanges with the website are encrypted in transit (HTTPS). Access to internal tools is on a named-user basis, protected by strong authentication and limited to those who need it. We apply data minimisation: we ask only for the fields useful to the stated purpose, and we delete the data at the end of the planned retention period.

8. Your rights

What you can ask for

The GDPR gives you a right of access to your data, rectification if it is inaccurate, erasure, restriction of processing, objection (in particular to direct marketing), and portability for the data you provided to us. You can withdraw your consent at any time, without affecting processing already carried out. Under French law, you can also give directions on what happens to your data after your death.

How to exercise them

Write to hello@neurixis.ai setting out your request. We reply within one month, extended to three months if the request is complex, in which case we tell you. If serious doubt remains as to your identity, we may ask for proof.

Complaint to the CNIL

If our answer does not satisfy you, you can lodge a complaint with the French data protection authority:
CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
cnil.fr

9. Traffic measurement

Plausible Analytics

We use Plausible Analytics to measure website traffic. The tool sets no cookie, creates no persistent identifier and does not track anyone across sites. It produces aggregated statistics (number of visits, pages viewed, country, traffic source) that cannot identify you. The data is hosted in the European Union.

10. Cookies and trackers

Where to find out more

The list of trackers, their purpose, their lifetime and how to change your choice are set out in our cookie policy. No tracker subject to consent is set before you have accepted it.

11. Changes to this policy

Updates

We adapt this policy when our processing activities, our tools or the regulations change. The date of the last update appears at the top of the page. If a change is significant, we tell you by a suitable means, for example a message on the website.

Back to home